CPG 2.0 is CISA's current voluntary baseline for critical infrastructure cybersecurity, now realigned to NIST CSF 2.0 with a new Govern function. If you run security for a regulated organization, your next move is straightforward: pull the CPG Checklist, run the CSET assessment module, and score your gaps across all six functions, Govern, Identify, Protect, Detect, Respond, and Recover, before you touch a single control.
TL;DR:
- Assign clear ownership for every cybersecurity goal and establish regular oversight to ensure accountability, especially for supply-chain and third-party risks.
- Maintain a current asset inventory focusing on internet exposure, unsupported software, and sensitive data connections, then validate remediation efforts with measurable metrics.
- Implement phishing-resistant multi-factor authentication for all critical accounts and test backup restorations regularly to ensure rapid recovery capabilities.
- Conduct quarterly detection testing and tabletop exercises to verify alerting effectiveness and preparedness for actual incidents.
- Rapidly demonstrate progress within 90 days through evidence documentation, prioritizing quick wins like asset inventory, secure MFA, and backup testing to build credibility.
Table of Contents
- What Changed in CPG 2.0 and Why It Matters
- Govern: What Leaders Must Do to Make CPGs Stick
- Identify: Inventory, KEV Remediation, and Third-Party Validation
- Protect: Baseline Technical Controls and Operational Practices
- Detect: Telemetry, Logging, and Validating Detection Capability
- Respond: Incident Reporting, Playbooks, and CIRCIA Interaction
- Recover: Backup Validation, Restoration Testing, and Continuity
- How to Use the CPG Checklist, Worksheet, and CSET Module
- Applying CPGs to IT vs OT and to Small & Medium Organizations
- Prioritization, Metrics, and Reporting CPG Progress to Leadership
- Quick-Start Checklist for Technical Owners (90 to 180 Days)
- Publisher Perspective: Where CPG Adoption Actually Stalls
- Turn Your CPG Gaps Into a Funded Roadmap
- Sources
What Changed in CPG 2.0 and Why It Matters
CISA released Cross-Sector Cybersecurity Performance Goals 2.0 on December 11, 2025, folding in three years of operational feedback from the original CPG rollout and rebuilding the framework around NIST CSF 2.0. The headline change is structural, not cosmetic. CPG 1.0 organized goals loosely around technical controls. CPG 2.0 restructures everything under the same six functions NIST CSF 2.0 uses, which means a security leader who already reports against NIST can now map CPG progress directly onto that reporting without building a separate translation layer.
The addition that matters most is Govern. It did not exist as a standalone function in the original CPGs. CISA added it because operational data from three years of implementation showed a pattern: organizations with the technical controls in place still failed during incidents when nobody owned the decision-making, budget approval, or vendor oversight tied to those controls.
CPG 2.0 also expands sector-specific goals, or SSGs, developed jointly with Sector Risk Management Agencies for industries like energy, healthcare, and water. These sit on top of the cross-sector baseline rather than replacing it. An energy operator works through the same six functions everyone else does, then layers on SSG requirements tuned to grid reliability and physical safety concerns.
A few things to know about how CISA intends CPG 2.0 to be used:
- It is a floor, not a maturity model. CISA explicitly frames these goals as minimum risk-reduction actions, not a full compliance framework.
- Every goal ships with cost, complexity, and impact ratings, so you can prioritize by effort versus payoff instead of guessing.
- CISA built the update to favor achievable, high-impact actions rather than aspirational controls that only large enterprises can fund.
- The framework does not replace frameworks like SOC 2, HIPAA, or CMMC. It sits underneath them as a baseline you should already have covered.
If your organization has spent the last two years chasing a specific compliance framework, CPG 2.0 gives you a faster gap check before your next audit cycle, and a shared vocabulary for talking to regulators and insurers about baseline hygiene.
Govern: What Leaders Must Do to Make CPGs Stick
Govern is the function that separates organizations with real cybersecurity accountability from organizations with a policy binder nobody reads. CISA built it because technical controls fail quietly when no named person owns them.
Three things need to happen at the leadership level:
- Assign named ownership for every CPG function, not a department, an actual person with authority to approve spending.
- Set a recurring oversight cadence, typically quarterly, where risk posture gets reviewed against the CPG scorecard.
- Extend oversight to supply-chain and managed-service relationships, since a vendor breach counts against your Govern maturity just as much as an internal one.
Board-level reporting should track a small set of governance KPIs: percentage of CPG goals with a named owner, time since last third-party risk review, and whether budget requests tied to CPG gaps were approved or deferred. A related discipline, accountability scoring in governance decision making, offers a useful model for quantifying how well ownership actually translates into action rather than just existing on paper.
Pro Tip: Bring your board a one-page Govern scorecard before you bring them a technical remediation list. Executives fund accountability gaps faster than they fund abstract risk scores.
Energy operators managing multi-entity governance structures should look at how cybersecurity governance in energy programs assign oversight across operating units, since a single named owner rarely covers a distributed utility footprint.

Identify: Inventory, KEV Remediation, and Third-Party Validation
You cannot score CPG progress against assets you have not counted. The Identify function starts with a working inventory, not a spreadsheet from two audits ago.
An actionable inventory for CPG scoring needs to answer three questions per asset: what is internet-facing, what runs unsupported software, and what touches sensitive data or OT processes. Structure it by exposure, not by department, since that is how attackers see your network.
- Build and maintain an asset inventory that flags internet exposure, OT connectivity, and end-of-life software.
- Cross-reference every internet-facing asset against CISA's Known Exploited Vulnerabilities catalog on a set schedule, not ad hoc.
- Track KEV remediation as a hard metric: days from disclosure to patch, not just "patched or not."
- Use vendor attestations for lower-risk third parties and independent penetration testing for anything touching regulated data.
Independent validation matters more than most teams assume. A vendor's self-reported security questionnaire tells you what they claim. A penetration test or CSET-based assessment tells you what is actually true, which is the gap CISA's CPG scoring is designed to close.
Protect: Baseline Technical Controls and Operational Practices
Protect is where most of the CPG budget conversation happens, because this function covers the controls that show up on every insurance questionnaire and every audit checklist.
Phishing-resistant multifactor authentication tops the list, especially for administrative and privileged accounts. Password-based MFA that relies on SMS or push notifications no longer meets the bar CISA sets for high-risk accounts, since both are vulnerable to social engineering and interception.
Least-privilege access controls come next. If every admin account has domain-wide rights, one compromised credential becomes a full-network incident instead of a contained one.
- Deploy phishing-resistant MFA for all administrative and remote-access accounts.
- Segment networks so a breach in one zone cannot reach OT systems or sensitive data stores.
- Reduce internet-facing services to the minimum required for business operations, and harden what remains.
- Encrypt backups and test restoration on a fixed schedule, not only after an incident forces the question.
Staff training deserves the same rigor as technical controls. A phishing simulation program that runs once a year tells you nothing useful. Quarterly testing with real remediation for repeat failures produces the behavior change CPG scoring is actually trying to measure.
Detect: Telemetry, Logging, and Validating Detection Capability
Detect asks a blunt question: if an attacker is inside your network right now, would you know? Most organizations without dedicated security operations cannot answer that honestly.
CISA's baseline expectation is log collection from endpoints, network boundaries, and identity systems, retained long enough to support investigation, typically a minimum of several months depending on your regulatory obligations. Logs stored on the same systems they monitor do not count, since an attacker who gains admin access can simply delete them.
Small teams without a 24/7 security operations center have real options that meet CPG expectations without building an in-house SOC:
- Managed detection and response services that provide monitoring coverage outside business hours.
- Cloud-native logging and alerting built into platforms you already use, configured correctly rather than left on defaults.
- Scheduled log reviews with a documented escalation path, even if it is not continuous monitoring.
Testing detection matters as much as building it. A tabletop exercise that walks through a ransomware scenario exposes gaps in alerting and escalation faster than any policy review. Penetration testing validates whether your detection tools actually fire when someone tries to move laterally, rather than just when a scanner runs a known signature.
Respond: Incident Reporting, Playbooks, and CIRCIA Interaction
Respond is the function most organizations discover they are unprepared for during an actual incident, not before.
CISA expects a documented incident response playbook with defined roles, escalation timelines, and communication templates ready before an incident, not drafted during one. The playbook should specify who contacts CISA, who contacts legal counsel, and who contacts affected customers, with those decisions made in advance.
Reporting matters here too. Organizations should know how to reach CISA directly at report@cisa.gov, and understand how that reporting relationship interacts with obligations under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which sets mandatory reporting timelines for covered entities experiencing substantial incidents.
- Maintain a written IR playbook covering roles, timelines, and external communication templates.
- Run at least one full tabletop exercise annually, with findings tracked to remediation, not filed and forgotten.
- Document evidence of playbook testing, since auditors and insurers increasingly ask for proof, not policy statements.
- Understand your CIRCIA reporting obligations separately from voluntary CISA notifications, since the timelines and triggers differ.
An untested playbook is a document, not a capability. The exercise is what turns it into one.
Recover: Backup Validation, Restoration Testing, and Continuity
Recover asks whether you can actually get back online, not whether you have a backup solution installed somewhere.
CISA's baseline expects frequent, tested backups with documented recovery time objectives (RTO) and recovery point objectives (RPO), meaning you know both how long restoration takes and how much data loss is acceptable before it happens, not after.
- Test full restoration from backup on a scheduled basis, not just backup completion status.
- Document RTO and RPO targets for your most critical systems, and validate that actual restoration times meet them.
- Review architecture for single points of failure that would prevent parallel recovery during a widespread incident.
- Maintain a written restoration runbook that a team member other than your lead engineer could follow under pressure.
Sector nuances matter here. Energy operators need recovery plans that account for physical safety systems that cannot simply restart on a schedule. Healthcare organizations face recovery windows constrained by patient care continuity, where a four-hour outage carries a different weight than it does for a professional services firm. Build your RTO targets around your sector's actual constraints, not a generic industry average.
How to Use the CPG Checklist, Worksheet, and CSET Module
CISA built three tools specifically so you do not have to build your own tracking system from scratch: the CPG Checklist, the CPG Worksheet, and the CSET assessment module.
- Run a baseline assessment. Work through the CPG Checklist function by function, marking each goal as met, partially met, or not started.
- Map findings to cost, complexity, and impact. The checklist and worksheet both include CISA's own estimated ratings for each goal, letting you sort gaps by effort versus payoff instead of tackling them in whatever order feels urgent.
- Build a prioritized roadmap. Use the worksheet's estimates to sequence a 90-day quick-win phase and a 180-day structural phase, weighted toward low-cost, high-impact goals first.
- Run the assessment inside CSET. CISA's Cyber Security Evaluation Tool includes a dedicated CPG module that produces repeatable, exportable results you can rerun quarterly to show trend lines instead of a single snapshot.
- Package results for stakeholders. CSET output converts more easily into board-ready reporting than a manual spreadsheet, since it standardizes scoring across assessment cycles.
Pro Tip: Run your first CSET assessment before you touch a single remediation project. Baseline scores you take after starting fixes make it impossible to prove the improvement later.
Applying CPGs to IT vs OT and to Small & Medium Organizations
CISA's cost and complexity ratings assume an IT environment where you can patch a server on a maintenance window without shutting down a production line. That assumption breaks down fast in operational technology.
A "low-complexity" goal like network segmentation might take an afternoon on a corporate network. On a plant floor running legacy programmable logic controllers, the same goal can require a change-control process, a maintenance outage, and sign-off from a control systems engineer who has veto power over anything that touches uptime. Guidance built for OT cybersecurity environments walks through how to re-score CISA's IT-centric ratings realistically for industrial settings.
- Re-evaluate every "low-complexity" CPG goal against your actual OT change-management process before committing to a timeline.
- Document compensating controls and formal risk acceptance decisions anywhere the standard CPG action is not feasible on OT systems.
- Small and medium organizations without a full security team should phase implementation, tackling Identify and Protect fundamentals before Detect and Respond capabilities that require ongoing monitoring investment.
- Bring in a virtual CISO or external assessor when internal staff lack the bandwidth to run a CSET assessment and translate results into a funded roadmap, which is the point where most SMBs stall out on their own.
Prioritization, Metrics, and Reporting CPG Progress to Leadership
Boards do not want a list of unpatched vulnerabilities. They want to know whether risk is going down and whether the budget request in front of them is worth approving.
A workable KPI set translates technical work into decisions:
- Percentage of CPG goals implemented per function, tracked quarter over quarter.
- KEV remediation rate, measured as days from disclosure to patch across your internet-facing assets.
- Mean time to detect (MTTD) and mean time to respond (MTTR) for confirmed security events.
- Backup restoration success rate, tested rather than assumed.
NIST's guidance on information security performance measurement reinforces a principle worth internalizing: metrics only earn their place on a dashboard when they drive a decision, not when they simply look busy on a slide.
For expensive CPG goals, run a straightforward cost-benefit comparison: the cost of the control against the realistic cost of the incident it prevents, including downtime, regulatory penalties, and client attrition. That framing moves the conversation from "security wants money" to "here is what an unpatched gap is actually worth in exposure."
A one-page executive dashboard works better than a slide deck. Include function-level completion percentages, your top three open risks by impact rating, KEV remediation rate, and one governance metric showing accountability is active, not theoretical. Report it monthly to the security lead and quarterly to the board.
Quick-Start Checklist for Technical Owners (90 to 180 Days)
Visible progress in the first 90 days builds the credibility you need to fund the harder 180-day work. Sequence matters more than volume here.
First 90 days:
- Complete an asset inventory flagging every internet-facing and OT-connected system.
- Cross-reference that inventory against the CISA KEV catalog and remediate confirmed matches first.
- Enable phishing-resistant MFA for every administrative and remote-access account.
- Test backup restoration on your most critical systems and document the actual RTO you measured, not the one you assumed.
Days 90 to 180:
- Implement network segmentation between IT, OT, and sensitive data environments.
- Enable centralized logging across endpoints and identity systems, with retention that meets your sector's obligations.
- Run a full tabletop incident response exercise and document findings and remediation owners.
- Complete third-party risk reviews for vendors with access to sensitive systems or data.
Produce evidence as you go, not after the fact. Screenshots of MFA enrollment, closed remediation tickets tied to specific KEVs, backup test results with timestamps, and a one-page board summary all count as the artifacts auditors, insurers, and your own leadership will eventually ask to see. Teams building this kind of evidence trail often start with structured security templates rather than building documentation formats from scratch under deadline pressure.
Pro Tip: Keep a running "evidence folder" from day one of your 90-day sprint. Retroactively assembling proof of what you did six months ago costs far more time than saving it as you go.
Publisher Perspective: Where CPG Adoption Actually Stalls
Most organizations that stall on CPG 2.0 do not stall on the technical work. They stall on translation, turning a checklist item into a funded project with an owner and a deadline. That is the gap a vCISO engagement is built to close.
In practice, a vCISO engagement maps each client's CPG gaps directly onto a prioritized roadmap, sequencing quick wins against the same cost, complexity, and impact logic CISA publishes, then produces the evidence artifacts leadership and auditors actually ask for: assessment output, a scored gap list, and a board-ready one-page dashboard.
The pattern holds across regulated sectors. A firm carrying HIPAA or CMMC obligations already has most of the audit trail it needs; what it lacks is the structure to connect that work to CPG's six functions in language a board will fund. That structural gap, more than any single missing control, is what keeps otherwise capable security teams from getting credit for the progress they have already made.
— vCISO
Turn Your CPG Gaps Into a Funded Roadmap
Reading the checklist is the easy part. Turning a scored gap list into a funded, sequenced roadmap with an owner on every line item is where most internal teams run out of bandwidth, and where a vCISO engagement pays for itself fastest.

Some providers combine hands on vCISO advisory with a compliance SaaS platform built for exactly this kind of work: automated assessments, prioritized risk roadmaps, policy development, and board-ready reporting, serving regulated, high-stakes industries. If your team is running lean and cannot dedicate a full-time CISO to translating CPG 2.0 into a 90-day sprint, this is the practical middle ground between doing it all in-house and hiring a full executive.
Organizations already tracking SOC 2, HIPAA, PCI DSS, or CMMC obligations tend to see the fastest wins here, since most of the underlying evidence already exists and just needs the right structure. Start with a CPG-focused readiness assessment through CisoSafe to get a scored baseline and a prioritized roadmap built around your actual budget and team size.
Sources
Bookmark these directly from CISA and NIST rather than relying on secondhand summaries, since CISA updates checklist ratings and sector guidance periodically.
- CISA Unveils Enhanced Cross-Sector Cybersecurity Performance Goals | CISA
- CISA CPG Checklist | CISA
- NIST Cybersecurity Framework (CSF)
For incident reporting, reach CISA directly at report@cisa.gov, and confirm whether your organization also carries mandatory reporting obligations under CIRCIA separate from voluntary CISA notification.
